Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpbakery

First CVE: Nov 16, 2020Active for: 6 yearsTotal CVEs: 15
14.0
VTI Score
Low

WPBakery's vulnerability profile centers on its widely adopted WordPress page-builder plugin, which extends the core WordPress ecosystem with visual website-design capabilities. The recurring weaknesses reflect the plugin's role processing user-supplied content and file paths: cross-site scripting and path-traversal flaws recur across its disclosures, typical of web-facing content-management extensions. Defenders should track this vendor's updates alongside their WordPress deployments and validate that user-privilege and input-filtering controls are appropriately configured; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpbakery over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 16, 2020
5 years ago
Most Recent CVE
Oct 18, 2025
280 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-5709HIGH
The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it pos
Aug 6, 20248.827NONO
CVE-2025-11160MEDIUM
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS module in all versions up to, and including, 8.6.1. This is due to ins
Oct 15, 20255.420NONO
CVE-2025-4968MEDIUM
The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Page Builder elements (Copyright Element, Hover Box, Separat
Jul 24, 20255.420NONO
CVE-2025-10006MEDIUM
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider_vc' shortcode in all versions up to, and including, 8.6 due
Oct 18, 20255.419NONO
CVE-2025-11161MEDIUM
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading shortcode in all versions up to, and including, 8.6.1. This is
Oct 15, 20255.419NONO
CVE-2025-7502MEDIUM
The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcodes in all versions up to, and including, 8.5 due to in
Aug 6, 20255.419NONO
CVE-2024-5708MEDIUM
The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 7.7 due to insufficien
Aug 6, 20245.418NONO
CVE-2024-1842MEDIUM
The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in all versions up to, and including, 7.5 due to insufficient in
May 2, 20245.418NONO
CVE-2024-1805MEDIUM
The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 7.5 due to insufficient input
May 2, 20245.418NONO
CVE-2024-43953MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcodingplace Classic Addons – WPBakery Page Builder classic-addons-wpbakery-
Aug 29, 20245.417NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
93%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (6.7%)
Unknown0 (0.0%)
Required14 (93.3%)
Privileges Required
Low15 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpbakery.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpbakery — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpbakery's Products

View all 3 CNAs →

Top CWEs